CVE-2026-66909Disclosure(apache / cxf)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache cxf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cxf

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
cxf

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-06: 3Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-06: 3Technical Details · 2026-08-07: 108-0608-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-063
Disclosure3
2026-08-071
Patch1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Patch

    ☕ Apache CXF CVSS 9.8: unsafe Java deserialization of inbound JMS ObjectMessages with zero type restrictions. Any attacker who can drop a message on the queue gets RCE. Patch now. CVE-2026-66909 #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-66909?utm_campaign=x https://t.co/dOyGDuDGJ1

    Post summary

    CVE-2026-66909 is a high‑severity flaw in Apache CXF that permits remote code execution via unsafe Java deserialization in JMS ObjectMessages; a vendor patch has been released.

    00000464
    875 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Apache CXF JMS ObjectMessage Unsafe Deserialization (CVE-2026-66909) Apache CXF JMS transport in org.apache.cxf:cxf-rt-transports-jms deserializes inbound JMS ObjectMessage bodies via native Java deserialization without type restrictions. An attacker who can send to the JMS destination can deliver a malicious serialized object to trigger DoS or potentially RCE if gadget chains exist on the classpath. 👉Affected: org.apache.cxf:cxf-rt-transports-jms < 3.6.12, < 4.1.8, < 4.2.3 | Upgrade to 3.6.12 / 4.1.8 / 4.2.3

    Post summary

    Disclosed a critical Apache CXF JMS deserialization flaw (CVE‑2026‑66909) with potential RCE, and provided version upgrade guidance to remediate.

    00000108
    282 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker … https://www.cve.org/CVERecord?id=CVE-2026-66909 ----- Traducción: CVE-2026-66909 El … http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-66909, detailing a deserialization flaw in Apache CXF’s JMS transport, but does not provide a PoC, exploit, or patch information.

    0000041
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker … https://www.cve.org/CVERecord?id=CVE-2026-66909

    Post summary

    The post announces a new vulnerability (CVE‑2026‑66909) in Apache CXF's JMS transport that deserializes any inbound JMS ObjectMessage without type checks, outlining the technical flaw but providing no PoC, exploit, or patch information.

    000001.8K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecxf---

Explore more